ARA-C01 exam dumps

ARA-C01 practice question 1 of 434

SnowPro® Advanced: Architect. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ARA-C01 Question 1

Single answerDomain 1.0: Account and Security (25%)

A global financial services company uses a Snowflake organization with separate PROD, DEV, and TEST accounts. The security team must allow a central identity provider (IdP) group called FINANCE_ANALYSTS to access only the PROD account through SSO, while ensuring that user and role administration remains centralized and auditable. The company also wants to minimize manual user lifecycle management inside individual accounts. Which approach best meets these requirements?

  1. A

    Configure SAML2 security integration separately in each Snowflake account, create local users in PROD for each analyst, and grant account roles directly to those users.

  2. B

    Use SCIM provisioning from the IdP into the PROD account only, map the FINANCE_ANALYSTS IdP group to Snowflake account roles, and manage users independently in each account.

  3. C

    Set up federated authentication with the central IdP, provision users and groups through SCIM where supported, and use account-level access controls in PROD so only the FINANCE_ANALYSTS group is assigned roles in that account.

  4. D

    Create users manually in the organization account, grant them organization-level roles for PROD data access, and rely on those organization roles to enforce schema-level permissions inside the PROD account.

Show answer and explanation

Correct answer: C

Explanation

The best answer is to centralize authentication and lifecycle management in the enterprise IdP and use Snowflake account-level RBAC to restrict access to the PROD account. In practice, Snowflake supports federated authentication using SAML 2.0 and user provisioning through SCIM integrations, which helps reduce manual creation, deactivation, and group maintenance of users. For authorization, access to data objects remains governed by account roles inside the target Snowflake account; organization-level constructs do not replace account-level privileges for database objects. This design supports least privilege, centralized auditability, and cleaner identity governance in multi-account architectures. Relevant Snowflake guidance includes documentation on federated authentication, SCIM provisioning, and the distinction between organization-level administration and account-level access control.

  • A. Incorrect.

    Incorrect. While separate SAML integrations per account can work technically, this approach does not minimize manual lifecycle management because it depends on local user creation in PROD. Granting account roles directly to manually managed users also increases administrative overhead and audit complexity. In a multi-account environment, Snowflake best practices favor centralized identity management with federation and automated provisioning rather than per-account manual user administration.

  • B. Incorrect.

    Incorrect. SCIM provisioning can reduce manual lifecycle work, but this option still frames identity management as independent in each account and does not address centralized, auditable administration across the environment as effectively as a broader federated model. It is also incomplete because simply provisioning into PROD only does not fully align with the stated requirement for centralized administration patterns across the organization. The key architectural goal is to centralize authentication and user lifecycle with the enterprise IdP, while assigning access only in the target account.

  • C. Correct.

    Correct. This approach aligns with Snowflake security best practices for enterprise identity management: use federated authentication with a central IdP for SSO, automate user and group lifecycle through SCIM where supported, and keep authorization scoped to the PROD account by assigning only the FINANCE_ANALYSTS group to the relevant account roles there. This minimizes manual user management inside Snowflake accounts, keeps administration centralized and auditable through the IdP, and ensures users can access only the intended account based on role assignments and account configuration.

  • D. Incorrect.

    Incorrect. Organization-level roles do not replace account-level RBAC for database, schema, and object permissions within a Snowflake account. They are used for organization-scoped administration tasks, not for enforcing schema-level data access in PROD. Manually creating users also conflicts with the requirement to minimize manual lifecycle management.

Timed practice exam

Take a ARA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam